Many major brand mobile apps not secure on Android, says study

Research from app development firm claims mobile apps from big-name brands are full of security holes that can expose sensitive information

In a study on mobile applications and their level of security, RIIS, LLC, a firm that specializes in mobile app development, said that some of the nation's top brands, including airlines, retail outlets, entertainment companies, and insurance companies, are producing applications for Android that place users and their personal information at risk.

The data comes from a study of twenty Android applications by RIIS, and how well they align to the OWASP Top 10. Of the twenty applications tested, only four were developed in such a way that when matched to the OWASP Top 10, they had no flaws at all. The other 16 however had at least one issue that could be problematic.

[Which smartphone is the most secure?]

Further, many of the applications tested are consumer focused, including Wal-Mart, Delta, Facebook, Geico, Ticketmaster, and Speedway. This means that the likelihood that they are on a given network is relatively high, especially the travel applications. The platform they're developed for is an important risk consideration too, as research from Strategy Analytics, says that global smartphone shipments grew to a record 230 million units in the second quarter of 2013, and more than 80 percent of them were running Android.

Delta's 'Fly Delta' application, along with Geico's application were the worst applications, with insecure data storage, poor authorization and authentication, broken cryptography, and sensitive information disclosure, issues discovered in each one.

When asked for additional details, Godfrey Nolan, the lead researcher in the study, told CSO that Delta's application stores the user's password in an encrypted in a SQLite database.

"However the key is in the APK which can be reverse engineered back into source code using some simple tools available on the internet," he explained.

As for the other problematic applications, Geico's tool also exposed login information, as did the app from Ticketmaster. The application form LiveNation doesn't use any encryption, and stored the login details in clear text.

CSO asked Nolan if he felt that the rush to adopt cloud and BYOD is creating an environment where mobile development teams are pushed to produce products and code, while security is added after the fact.

"I don't think this is even on the radar for most companies," he said.

In fact, when questioned by RIIS, Nolan said that many of the developers the spoke to reacted negatively, as if to say that the issues that were discovered were not something they were concerned with, thus trading security for usability.

[Slideshow: Mobile security: How gadgets evolved]

His advice is for security staff to apply mobile security scanning techniques such as those outlined in the OWASP Top 10, in order to ensure the organization knows what apps are insecure before allowing them to be installed on any BYOD or company devices.

However, on the other side of that coin, the applications developed by Wells Fargo, Chase, State Farm, and the Internal Revenue Service, were completely clean, and secured when judged against the OWASP list.

All things considered, RIIS says that the safest applications don't store any login information or sensitive user data on an Android device.

"It is common practice (and a fundamental security flaw) to store the username and password encrypted in a SQLite database or shared preferences folder with a hardcoded encryption key which can be found by decompiling the APK," the report adds.

The full report is available here, but registration is required.

Join the Good Gear Guide newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags RIISmobile applicationsAndroid OSsecuritymobile securitymobile

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Steve Ragan

CSO (US)
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?